CVE-2026-21904 PUBLISHED

Junos Space: ilpFilter field on nLegacy.jsp is vulnerable to reflected cross-site script injection

Assigner: juniper
Reserved: 05.01.2026 Published: 09.04.2026 Updated: 10.04.2026

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Juniper Networks Junos Space allows an attacker to inject script tags in the

list filter field that, when visited by another user, enables the attacker to execute commands with the target's permissions, including an administrator.

This issue affects all versions of Junos Space before 24.1R5 Patch V3.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 5.1

Product Status

Vendor Juniper Networks
Product Junos Space
Versions Default: unaffected
  • affected from 0 to 24.1R5 Patch V3 (excl.)

Exploits

Juniper SIRT is not aware of any malicious exploitation of this vulnerability.

Workarounds

There are no known workarounds for this issue.

Solutions

The following software releases have been updated to resolve this specific issue: 24.1R5 Patch V3, and all subsequent releases.

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') CWE